← Back to search

CVE-2026-63248

6.5 MEDIUMpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows anonymous clients to access diagnostics nodes without proper authorization, exposing sensitive security information. This matters because it can lead to unauthorized access to critical system details.
Exploitability
Exploitation is relatively easy with a None/None endpoint; more complex over SignAndEncrypt but still feasible.
Blast radius
If exploited, this could reveal usernames, login history, and security policies, impacting multiple active sessions.
Prioritized remediation
Update to Eclipse Milo versions 1.1.5 or later to apply necessary access control fixes.
auth-bypassinfo-leaksecurity-diagnostics

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagnostics for other active sessions, exposing usernames, login history, authentication mechanisms, security modes and policies, and public client certificates.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses

CWE-862

Vendors

eclipse

Products

milo

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.